CVE-2025-30065: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
Published Apr 1, 2025
·Updated
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code
Users are recommended to upgrade to version 1.15.1, which fixes the issue.
Affected Software
3 affected componentsFixes available
Apache Parquet<1.15.0
maven/org.apache.parquet:parquet-avro<1.15.1
1.15.1
Apache Parquet Java<1.15.1
Remediation
Patch Available
Event History
Jan 29, 2024
News Published
01:29 AM
Apr 1, 2025
CVE Published
via MITRE·07:53 AM
Data Sourced
via MITRE·07:53 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
RemedyAffected Software
Advisory Published
via GitHub·09:30 AM
Apr 3, 2025
News Published
via BleepingComputer·09:29 PM
News Published
via BleepingComputer·09:30 PM
Apr 7, 2025
News Published
via The Register·12:15 AM
News Published
via The Register·12:21 AM
May 6, 2025
News Published
via BleepingComputer·06:16 PM
May 10, 2025
Known Exploited
06:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-30065?
CVE-2025-30065 has been identified with a critical severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-30065?
To fix CVE-2025-30065, upgrade to Apache Parquet version 1.15.1 or later.
3
Which versions of Apache Parquet are affected by CVE-2025-30065?
Apache Parquet versions 1.15.0 and earlier are affected by CVE-2025-30065.
4
What specific vulnerability does CVE-2025-30065 address?
CVE-2025-30065 addresses a schema parsing vulnerability in the parquet-avro module.
5
What could happen if I don't address CVE-2025-30065?
Failure to address CVE-2025-30065 could allow attackers to execute arbitrary code on your system.